Ensuring Data Protection for Third Parties: Best Practices | UpGuard
ID: 9fb9709f-865a-5178-8e3c-57a380a5632d
STIX ID: report--9fb9709f-865a-5178-8e3c-57a380a5632d
Feed Name: UpGuard Blog
This is a guidance document on third-party data risk and vendor risk management: it outlines the risks introduced when external providers handle sensitive data, summarizes relevant legal and regulatory obligations (GDPR, CCPA, HIPAA), and provides best practices and a step-by-step approach to build a Vendor Risk Management program (vendor selection, assessments, controls, monitoring, encryption, audits, staff training, and incident response). It cites the 2013 Target third-party breach as an example but does not present a new incident analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
